logoalt Hacker News

modelesstoday at 8:12 PM0 repliesview on HN

Personally I hate when I use a passkey but then still get hit with an SMS second factor step. A passkey should be enough, unless I'm changing my recovery email or withdrawing a million dollars or something. Also there's still a lot of really bad UX around passkeys, both by browser/OS vendors and by individual apps, and unimplemented features like sharing.

Passkeys are the right thing but they need more work.